AI Assistants for Kubernetes: Secure Cluster Operations with MCP and Rafay ZTKA

Interact with Your Rafay Managed Kubernetes Clusters Using MCP-compatible AI clients

February 25, 2026

.png)

Model Context Protocol (MCP) is an open standard that enables AI assistants to securely interact with external tools and systems. When used with Kubernetes, MCP allows an AI assistant to execute operations (for example, kubectl commands), retrieve live cluster state, and reason about results without requiring users to manually copy and paste output into a chat interface.

This blog uses Claude Desktop as an example AI assistant. The same approach applies to any MCP-compatible AI client.

For platform administrators, this capability enables controlled, auditable, and policy-driven AI-assisted cluster operations.

Recommended Architecture: Local MCP Server with Rafay ZTKA Kubeconfig

For production environments, the recommended approach is to run the MCP server locally and connect to your Kubernetes cluster using a Rafay Zero Trust Kubectl Access (ZTKA) kubeconfig.

In this model:

This architecture aligns with zero-trust security principles and enterprise compliance requirements.

Security and Governance Considerations for Platform Admins

When integrating AI-driven access into Kubernetes environments, security, identity, and auditability must remain fully enforced. Rafay ZTKA ensures:

1. Authentication (AuthN) and Authorization (AuthZ)

The AI assistant does not bypass cluster security controls; it operates strictly within the RBAC boundaries of the authenticated user.

2. Audit Logging

This ensures AI-assisted operations are as traceable as manual administrative actions.

3. RBAC-Controlled Access

4. No Exposed Cluster Endpoints

Prerequisites

Before enabling MCP-based Kubernetes access, ensure the following components are installed and configured:

npm install -g mcp-server-kubernetes

Installing mcp-server-kubernetes globally ensures the executable is available in your system PATH, allowing your AI client to invoke it correctly.

{
  "mcpServers": {
    "kubernetes": {
      "command": "mcp-server-kubernetes",
      "env": {
        "KUBECONFIG": "/path/to/ztka-cluster-config.yaml"
      }
    }
  }
}

Replace /path/to/ztka-cluster-config.yaml with the actual path to your ZTKA kubeconfig.

Connecting Your AI Client (Example: Claude Desktop)

After configuring the MCP server to use your ZTKA kubeconfig:

Start a new session and select the Kubernetes integration if prompted.

Once connected, the AI assistant can securely execute Kubernetes commands through the MCP server.

Validate the Integration

To verify the setup, try simple test commands such as:

On first use, your AI client will request permission to execute Kubernetes operations. Approve the request to continue.

Operational Recommendations for Platform Teams

Before rolling out this capability broadly:

Summary

By combining MCP with Rafay ZTKA, organizations can enable AI-driven Kubernetes interactions without compromising security, visibility, or compliance.

This integration provides:

While this guide demonstrates the workflow using Claude as an example AI client, the same architecture applies to any MCP-compatible assistant.

What's Next

We are developing a native Rafay MCP Server that will expose Rafay-specific discovery and action-oriented capabilities through MCP including multi-cluster operations, add-on and blueprint management, and more. Stay tuned for updates.